Operating
Access
Production surfaces are gated: enterprise identity
(Auth0) on member portals, scoped access codes on partner surfaces,
and contract-gated provisioning on licensed modules. Sessions use
hardened cookie settings; administrative actions are logged.
Evidence:
access review on request.
Operating
Change management
Every application is version-controlled with a full
change history. Our most critical files run under a canon governance
protocol: modification requires an explicit typed override, and file
hashes are verified against a baseline on a recurring schedule.
Evidence:
override log and baseline report on request.
Operating
Data protection
TLS everywhere; strict security headers (CSP, HSTS,
frame denial) on hardened surfaces; secrets in environment
configuration, never in code; data minimization by design, including
zero-retention patterns on our most sensitive tools and aggregation
floors on small-population statistics.
Evidence:
header scan and retention posture per surface.
Operating
Evidence and audit trails
Where documentation matters most we use append-only,
hash-chained ledgers, so records are tamper-evident and every export
carries verifiable provenance.
Evidence:
a chain segment and its verification, on request.
Operating
Availability
Independent external uptime monitoring with alerting,
health-check endpoints on every service, scheduled backups with
documented restore runbooks, and recovery-time objectives per system
class.
Evidence:
monitor history and the restore runbook for your system class.
Operating
Vendors
A small, reviewed set of subprocessors (hosting,
identity, email, analytics), documented in our vendor register with a
risk tier for each.
Evidence:
the vendor register, on request.
Aligned
SOC 2 control framework
We maintain controls aligned to the AICPA Trust
Services Criteria across security, availability and confidentiality.
That describes how we build and operate. It is not a certification.
Evidence:
the control mapping, on request.
Project-specific
Attestation-grade build
When an engagement warrants it we apply the SOC 2 build
checklist from the first commit: scoped access reviews, audit logging
on authentication and administrative events, rate limiting, pinned
dependencies, backup wiring, and an incident-response runbook naming
real people. Your project inherits the framework rather than paying to
invent it.
Evidence:
the checklist, and which items your deployment carries, in writing.